General Educational Information — For Educational Purposes Only, Not Professional Advice.
Smart Business Blueprint is not a law firm or accounting firm and does not provide tax, legal, or accounting services.
Laws change frequently and may differ based on individual circumstances.
Get Updates on New Texas Business Guides
Texas businesses face obligations under several overlapping privacy and data-security laws, including the Texas Data Privacy and Security Act, Texas's data breach notification law, and the Capture or Use of Biometric Identifier Act (CUBI). This guide covers all three, along with the industry-specific rules that often apply on top of them.
Quick Answer
- The Texas Data Privacy and Security Act (TDPSA), effective July 1, 2024, is Texas's comprehensive consumer data privacy law and applies to covered businesses that meet the statute's applicability requirements, subject to exemptions.
- Texas requires notice to affected individuals within 60 days of determining a data breach occurred.
- Breaches affecting 250 or more Texas residents also require notice to the Texas Attorney General within 30 days.
- The Capture or Use of Biometric Identifier Act (CUBI) requires notice and consent before capturing biometric identifiers for a commercial purpose.
- CUBI violations carry civil penalties of up to $25,000 per violation, enforced exclusively by the Texas Attorney General.
- Healthcare, financial services, and businesses that accept payment cards may face additional obligations under HIPAA, GLBA, and applicable PCI DSS standards.
Key Takeaways
- Texas's comprehensive privacy law, the TDPSA, is codified at Business and Commerce Code Chapter 541 and took effect July 1, 2024.
- Small businesses (as defined by the U.S. Small Business Administration) are generally exempt from the TDPSA, but must still get consent before selling sensitive data.
- Texas's data breach law is codified at Business and Commerce Code Section 521.053.
- The individual-notification deadline is 60 days; the Attorney General deadline (250+ residents) is 30 days.
- As of September 2023, AG breach notifications must be submitted electronically through the Attorney General's website.
- CUBI defines biometric identifiers narrowly: retina/iris scans, fingerprints, voiceprints, and hand or face geometry records.
- Businesses must destroy captured biometric identifiers within a reasonable time, and no later than the first anniversary of the date the purpose for collecting them expires, subject to statutory exceptions.
- Financial institution voiceprint data is exempt from CUBI, and GLBA-regulated entities are generally exempt from the TDPSA.
- Neither CUBI nor the TDPSA provides a private right of action under the statute. The Texas Attorney General has enforcement authority under both laws.
- An incident response plan prepared before a breach occurs significantly reduces the risk of missing statutory deadlines.
1. Texas's Data Security Legal Landscape
Texas businesses face obligations under several overlapping privacy and data-security laws. The Texas Data Privacy and Security Act governs how businesses collect, use, and sell Texas consumers' personal data generally. Layered on top of that are two more specific obligations: notifying people after a data breach, and getting consent before capturing biometric identifiers for commercial purposes.
2. The Texas Data Privacy and Security Act
The Texas Data Privacy and Security Act (TDPSA), codified at Texas Business and Commerce Code Chapter 541, is Texas's comprehensive consumer data privacy law. It was enacted through House Bill 4 during the 88th Texas Legislative Session and took effect July 1, 2024.
The TDPSA generally applies to any person or business that conducts business in Texas or produces products or services consumed by Texas residents, processes or sells personal data, and does not qualify as a small business under the U.S. Small Business Administration's size standards, subject to the statute's other applicability and exemption provisions. Unlike many other state privacy laws, the TDPSA does not set a minimum revenue or consumer-count threshold — coverage is instead based primarily on the small-business exemption and the entity- and data-level exemptions described below.
The TDPSA grants Texas consumers several rights over their personal data, including the right to access, correct, delete, and opt out of the processing of their data for purposes such as targeted advertising or sale. It requires covered businesses to provide clear privacy notices and implement reasonable data security practices, and imposes additional consent requirements before processing certain categories of sensitive data, including biometric data.
3. The Texas Data Breach Notification Law
Texas's breach notification requirements are found in the Texas Business and Commerce Code and apply to any person or business that conducts business in Texas and owns or licenses computerized data containing sensitive personal information.
4. Notifying Affected Individuals
Disclosure to affected individuals must be made without unreasonable delay and, in any case, no later than the 60th day after the business determines a breach occurred, with limited exceptions for law enforcement investigations or the time needed to determine the scope of the breach.
5. Notifying the Texas Attorney General
If a breach affects 250 or more Texas residents, the business must also notify the Texas Attorney General. Texas law requires this notification as soon as practicable and no later than the 30th day after the business determines that the breach occurred.
6. What Counts as Sensitive Personal Information
Sensitive personal information under Texas breach-notification law generally includes a person's name combined with a Social Security number, driver's license number, or financial account number, as well as certain health and biometric information. Understanding what qualifies is essential to determining whether an incident triggers the notification requirement at all.
7. Biometric Data in Texas: An Overview
As biometric identifiers — fingerprints, facial recognition, retinal scans, and voiceprints — become more common in commercial settings such as employee timekeeping and building access, Texas businesses need to understand the specific rules governing their capture and use, both under CUBI and, where applicable, the TDPSA's sensitive-data provisions.
8. The Capture or Use of Biometric Identifier Act (CUBI)
CUBI, codified in Chapter 503 of the Texas Business and Commerce Code, regulates how businesses may capture and use biometric identifiers for commercial purposes.
CUBI's Notice, Consent, and Destruction Requirements
| Requirement | What It Means |
|---|---|
| Notice | Individual must be informed before capture. |
| Consent | Individual must affirmatively consent before capture. |
| No sale/disclosure | Restricted, with limited statutory exceptions. |
| Destruction | Required within a reasonable time after the purpose for collection expires, and no later than the first anniversary of the date that purpose expires, subject to statutory exceptions. |
| Financial institution exemption | Voiceprint data held by financial institutions is excluded. |
10. CUBI Penalties and Enforcement
CUBI does not create a private right of action — individuals cannot sue directly under the statute. Instead, enforcement is handled exclusively by the Texas Attorney General.
11. Industry-Specific Requirements
12. Data Security Best Practices
Beyond the specific statutory requirements, Texas businesses benefit from implementing comprehensive data security programs, including regular security assessments and penetration testing, employee training on security and privacy practices, and maintaining cyber insurance coverage appropriate to the business's risk profile.
Better Practice
Conduct a data inventory identifying exactly what sensitive personal information and biometric data your business collects, where it's stored, and who has access — this single step makes both breach response and CUBI/TDPSA compliance dramatically easier.
13. Building an Incident Response Plan
Developing an incident response plan before a breach occurs — rather than improvising one under time pressure — helps ensure the business can meet Texas's 60-day and 30-day notification deadlines and reduces the risk of a rushed, incomplete response.
14. Common Mistakes
Mistake
Missing the 30-Day AG Notification Deadline
Businesses sometimes assume the 60-day individual-notice deadline also applies to Attorney General notification, missing the shorter 30-day requirement for breaches affecting 250+ residents.
Mistake
Capturing Biometric Data Without Notice and Consent
Rolling out fingerprint or facial recognition systems without first providing the required notice and obtaining consent creates direct CUBI exposure.
Mistake
No Retention or Destruction Policy for Biometric Data
CUBI requires destruction within a reasonable time and no later than the first anniversary of the date the purpose expires — indefinitely retaining biometric identifiers increases legal risk.
Mistake
Assuming the TDPSA Doesn't Apply
Some businesses assume Texas has no general privacy law and overlook TDPSA obligations entirely — an increasingly costly mistake given active Attorney General enforcement.
Mistake
Treating Breach Notification as a One-Size-Fits-All Process
Failing to distinguish between the individual-notice and AG-notice requirements — including their different deadlines and thresholds — can lead to incomplete compliance.
Mistake
No Incident Response Plan in Place Before a Breach
Scrambling to build a response process after a breach has already occurred often causes businesses to miss statutory deadlines.
Mistake
Overlooking Layered Industry-Specific Obligations
Businesses in healthcare, finance, or payment processing sometimes address Texas requirements without recognizing that HIPAA, GLBA, or applicable PCI DSS standards impose separate, additional obligations.
15. Compliance Checklist
- Determine whether the business qualifies for the TDPSA's small-business exemption, and confirm sensitive-data-sale consent requirements even if exempt.
- Data inventory identifies all sensitive personal information and biometric data collected.
- Notice and consent process in place before capturing any biometric identifier.
- Destruction schedule established for biometric identifiers, no later than the first anniversary of the date the collection purpose expires.
- Incident response plan drafted and tested before a breach occurs.
- Process in place to notify affected individuals within 60 days of a determined breach.
- Process in place to notify the Texas Attorney General within 30 days for breaches affecting 250+ residents.
- Electronic AG notification form procedures understood and ready to use.
- Industry-specific obligations (HIPAA, GLBA, applicable PCI DSS standards) mapped to the business's operations.
- Employee training on data security conducted regularly.
- Cyber insurance coverage evaluated against the business's actual risk exposure.
16. Primary Government Sources
Texas Business and Commerce Code, Chapter 503 — Biometric Identifiers (CUBI) (Texas Constitution and Statutes)
Texas Business and Commerce Code, Chapter 521 — Data Breach Notification
Texas Business and Commerce Code, Chapter 541 — Texas Data Privacy and Security Act
Texas Attorney General — Data Breach Reporting
Texas Attorney General — Texas Data Privacy and Security Act
17. Frequently Asked Questions
Does Texas have a comprehensive data privacy law?
Yes. The Texas Data Privacy and Security Act (TDPSA), effective July 1, 2024, is Texas's comprehensive consumer data privacy law. It gives Texas consumers rights to access, correct, delete, and opt out of certain processing of their personal data, and requires covered businesses to implement reasonable data security practices.
What is the Texas Data Privacy and Security Act?
The TDPSA, codified at Texas Business and Commerce Code Chapter 541, regulates how businesses collect, use, process, and sell Texas consumers' personal data. It grants consumer rights such as access, correction, deletion, and opt-out, requires clear privacy notices and reasonable security measures, and is enforced exclusively by the Texas Attorney General.
Does the Texas Data Privacy and Security Act apply to small businesses?
Small businesses, as defined by the U.S. Small Business Administration, are generally exempt from the TDPSA. However, even an exempt small business must still obtain consumer consent before selling sensitive personal data.
How quickly must a Texas business notify individuals after a data breach?
Notification must be made without unreasonable delay and no later than the 60th day after the business determines a breach occurred, subject to limited exceptions.
When must the Texas Attorney General be notified of a breach?
If the breach affects 250 or more Texas residents, the Attorney General must be notified as soon as practicable and no later than 30 days after the business determines the breach occurred.
Does Texas have a biometric privacy law like Illinois's BIPA?
Texas has its own biometric statute, CUBI, but it is narrower than Illinois's BIPA in some respects — most notably, CUBI does not create a private right of action, so individuals cannot sue directly under the statute.
What counts as a biometric identifier under Texas law?
CUBI defines a biometric identifier as a retina or iris scan, fingerprint, voiceprint, or record of hand or face geometry.
Do I need consent before using fingerprint timeclocks for employees?
Yes. Under CUBI, employers must inform employees before capturing their biometric identifiers and obtain consent, even for routine uses like timekeeping.
What are the penalties for violating CUBI?
Civil penalties of up to $25,000 per violation, which may only be pursued by the Texas Attorney General.
Can an individual sue a business directly under CUBI or the TDPSA?
Neither CUBI nor the TDPSA provides a private right of action under the statute. The Texas Attorney General has enforcement authority under both laws.
How long can a business keep biometric data it collects?
CUBI requires that captured biometric identifiers be destroyed within a reasonable time after the purpose for collecting them expires, and no later than the first anniversary of that expiration date, subject to limited statutory exceptions.
Are financial institutions exempt from CUBI or the TDPSA?
Voiceprint data retained by financial institutions or their affiliates is specifically exempt from CUBI's requirements. Separately, entities regulated under the Gramm-Leach-Bliley Act are generally exempt from the TDPSA.
What should a business do immediately after discovering a data breach?
Begin an investigation to determine the scope of the breach, consult legal counsel, and prepare to meet the applicable 60-day individual notification and, if applicable, 30-day Attorney General notification deadlines.